Password manager LastPass notified its customers of a second security breach in 2022, with the threat actor accessing customer data stored on a shared cloud service.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
A hacker who leaked one million genetic profiles from 23andMe in early October has returned with an even larger trove, this time dumping a little over four million files and including the DNA Relatives feature that allows for connections between relations to be made.
Second special directive from the TSA is requiring pipeline operators to implement specific mitigation measures and create contingency and recovery plans, though most of the details are being kept from the public.
The company arranged a payment of $200,000 through a third party, but customer data from the T-Mobile hack was subsequently seen for sale on dark net forums.
AI deepfakes were used to contact three foreign ministers, a US Governor, and a member of Congress around the middle of June via the Signal messaging app. Two of the officials received fake voicemail messages mocked up to use Rubio's voice, and another received an invite to join a chat.
Secure Service Edge (SSE) may be the architecture of the future by delivering connectivity and security tools from the cloud to reduce complexity, risk, and cost.
The importance of creating an interconnected security infrastructure for IoT is crucial. In a world where everything is communicating with everything else it is not just business critical but vital that everything from smart city networks down to individual smart devices is secure.
5G networks are exciting and open the door to many new possibilities for IoT, however it also comes with security risks as manufacturers rush to dominate the new untapped market their devices.
There's a need to secure offline, rather than online, microfinancing solutions. The future rests in the power of embeddable microchips and the power of process isolation by inserting a Linux-powered computer into the architecture of an non-secure IoT device to create a hardware Root of Trust.
It’s no secret that banking applications – both traditional and emerging fintech apps – still remain a prime target for financially-motivated cyberattacks. Cybercriminals are money-motivated, targeting the applications and institutions with the potential for the highest reward.










